GHSA-677m-j7p3-52f9
socket.io allows an unbounded number of binary attachments
Quick fix
GHSA-677m-j7p3-52f9 — socket.io-parser: upgrade to the fixed version with the command below.
npm install socket.io-parser@3.3.5Details
### Impact
A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.
### Patches
| Version range | Used by | Fixed version | |------------------|--------------------------------------------|---------------| | `>=4.0.0 <4.2.6` | `socket.io@4.x` and `socket.io-client@4.x` | `4.2.6` | | `>=3.4.0 <3.4.4` | `socket.io@2.x` | `3.4.4` | | `<3.3.5` | `socket.io-client@2.x` | `3.3.5` |
### Workarounds
There is no known workaround except upgrading to a safe version.
### For more information
If you have any questions or comments about this advisory:
- Open a discussion [here](https://github.com/socketio/socket.io/discussions)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/socketio/socket.io/security/advisories/GHSA-677m-j7p3-52f9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-33151[ADVISORY]
- https://github.com/socketio/socket.io/commit/719f9ebab0772ffb882bd614b387e585c1aa75d4[WEB]
- https://github.com/socketio/socket.io/commit/9d39f1f080510f036782f2177fac701cc041faaf[WEB]
- https://github.com/socketio/socket.io/commit/b25738c416c4e32fbff62ee182afa8f6d0dacf78[WEB]
- https://github.com/socketio/socket.io[PACKAGE]